Skip to content
Content type · 3,429 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–200 of 3,429 sort newestlargest fineoldest
€2,000 Comune di Velletri: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Comune di Velletri €2,000 on 2026-02-12 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +2 Education IP Address Processing Feb 12, 2026
€12,000 Based s.r.l.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Based s.r.l. €12,000 on 2026-02-12 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 5, 12, 13 +2 Personal Data Employees Supervisory Authorities Feb 12, 2026
€15,000 Depurazione Acqua S.r.l.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Depurazione Acqua S.r.l. €15,000 on 2026-02-12 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 4, 5, 6 +3 Processing Telecommunications Supervisory Authorities Feb 12, 2026
€6,000 Comune di Coccaglio: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Comune di Coccaglio €6,000 on 2026-02-12 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 IP Address Employees Processing Feb 12, 2026
€1,000 Sole Trader: Insufficient fulfilment of information obligations Italian Data Protection Authority (Garante) fined Sole Trader €1,000 on 2026-02-12 for: Insufficient fulfilment of information obligations. Italy ·Garante ·Art. 5, 13 Telecommunications Supervisory Authorities Cookies Feb 12, 2026
€5,000 Unleadmited S.r.l.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Unleadmited S.r.l. €5,000 on 2026-02-12 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 7 +1 Processing Telecommunications Cookies Feb 12, 2026
€4,000 Order of Physicians, Surgeons and Dentists of the Province of Macerata: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Order of Physicians, Surgeons and Dentists of the Province of Macerata €4,000 on 2026-02-12 for: Insufficient legal basis for… Italy ·Garante ·Art. 5, 6 Processing Public Authority Education Feb 12, 2026
€1,500 Sole Trader: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Sole Trader €1,500 on 2026-02-12 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 25 Processing Telecommunications Supervisory Authorities Feb 12, 2026
€30,000 Sportitalia Società Sportiva Dilettantistica a.r.l.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Sportitalia Società Sportiva Dilettantistica a.r.l. €30,000 on 2026-02-12 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 12, 17 Personal Data Telecommunications Supervisory Authorities Feb 12, 2026
€15,000 Bressanelli Galli Gelpi Porta & C. S.r.l.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Bressanelli Galli Gelpi Porta & C. S.r.l. €15,000 on 2026-02-12 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 7 +3 Insurance Processing Telecommunications Feb 12, 2026
€2,000 Comune di Monterotondo: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Comune di Monterotondo €2,000 on 2026-02-12 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 88 Education Processing Public Authority Feb 12, 2026
€150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested… Art. 5, 6 Personal Data Integrity and Confidentiality Principle Access Controls Feb 11, 2026
€30,000 Vodafone – PANAFON A.E.E.T.: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined Vodafone – PANAFON A.E.E.T. €30,000 on 2026-02-11 for: Insufficient fulfilment of data subjects rights. Greece ·HDPA ·Art. 12, 15, 18 Personal Data Telecommunications Supervisory Authorities Feb 11, 2026
€1,800 Landlord: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,800 on a Landlord. The landlord used video surveillance in rental apartments without having a sufficient legal basis. The original fine… SPAIN ·aepd ·Art. 6 Video Surveillance Controllers Monitoring Feb 6, 2026
€20,000 Tensa Art Design S.A: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 20,000 onTensa Art Design S.A.The DPA began investigating the controller's data processing activities, but the controller failed to… ROMANIA ·ANSPDCP ·Art. 58, 83 Supervisory Authorities Supervision Controllers Feb 5, 2026
€284,450 MediaLab.AI, Inc.: Insufficient legal basis for data processing The UK DPA has imposed a fine of GBP 247,590 (EUR 284,450) on MediaLab.AI, Inc.The controller of the image-sharing and hosting platform Imgur failed to implement age verification.… UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Minors Controllers Consent Feb 5, 2026
€10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Access Controls Controllers Feb 4, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Controllers Feb 3, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€10,000 FREE TECHNOLOGIES EXCOM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 10,000 on FREE TECHNOLOGIES EXCOM, S.L. The controller had reset user passwords and communicated the new passwords to the clients via… SPAIN ·aepd ·Art. 32 Encryption Integrity and Confidentiality Principle Security Feb 3, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Controllers Feb 3, 2026
€25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€1,000 Alliance for the Union of Romanians (AUR) Party: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Alliance for the Union of Romanians (AUR) Party. The controller failed to react adequately to a data subject's request to… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Personal Data Controllers Processing Agreement Feb 3, 2026
€25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +6 Criminal Data Personal Data Health Data Jan 30, 2026
€2,000 Federazione Nazionale Ordini Professioni Infermieristiche (FNOPI): Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Federazione Nazionale Ordini Professioni Infermieristiche (FNOPI) €2,000 on 2026-01-29 for: Insufficient legal basis for data… Italy ·Garante ·Art. 5, 6 Processing Telecommunications Supervisory Authorities Jan 29, 2026
€50,000 Università Telematica e-Campus: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Università Telematica e-Campus €50,000 on 2026-01-29 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 9 +1 Education Telecommunications Public Authority Jan 29, 2026
€12,000 Ministero della Cultura: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Ministero della Cultura €12,000 on 2026-01-29 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 Employees Processing IP Address Jan 29, 2026
€5,000 Dr. Paolo Montemurro: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Dr. Paolo Montemurro €5,000 on 2026-01-29 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 9 Healthcare Processing Telecommunications Jan 29, 2026
€10,000 Istituto tecnico industriale statale “Stanislao Cannizzaro” di Catania: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Istituto tecnico industriale statale “Stanislao Cannizzaro” di Catania €10,000 on 2026-01-29 for: Insufficient legal basis for… Italy ·Garante ·Art. 5, 6, 9 Education Public Authority Processing Jan 29, 2026
€12,000 Istituto San Giuseppe La Salle di Milano: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Istituto San Giuseppe La Salle di Milano €12,000 on 2026-01-29 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 IP Address Education Public Authority Jan 29, 2026
€565,000 Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 565,500 on Sportadmin i Skandinavien AB. The controller suffered a sucessfull cyber attack, resulting in personal and special category… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Health Data Jan 26, 2026
€5M FRANCE TRAVAIL: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 5,000,000 on FRANCE TRAVAIL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures,… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Health Data Jan 22, 2026
€4,850 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €4,850 on 2026-01-20 for: Insufficient technical and organisational measures to ensure… Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Processing Agreement Jan 20, 2026
€15,000 Continental Automotive Products SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €15.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 32 Security Controllers Accountability NL Jan 19, 2026
€1,200 Dental Clinic: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200 on a dental clinic. The controller used video surveillance in its clinic for security purposes, including a camera in the doctor's… SPAIN ·aepd ·Art. 5 Video Surveillance Controllers IP Address Jan 19, 2026
€25,500 Austrian DSB: Marketing agency violated GDPR by recording phone interviews without valid The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Legitimate Interest Personal Data Retention Period Jan 19, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Continental Automotive Products SRL. The controller failed to implement adequate technical and organisational measures,… ROMANIA ·ANSPDCP ·Art. 5, 32 Security Controllers Processing Agreement Jan 19, 2026
€1,500 Italian DPA fines butcher €1,500 for unlawful video surveillance lacking information signs The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +2 Video Surveillance Controllers Fairness & Transparency Jan 16, 2026
€21,650 Timegrip AS: Insufficient fulfilment of data subjects rights The Norwegian DPA has imposed a fine of EUR 21,650 on Timegrip AS. The controller had been tracking the working hours of employees at a company that went bankrupt. A former… NORWAY ·Datatilsynet ·Art. 15 Personal Data IP Address Controllers Jan 16, 2026
DSB Austria: No fine imposed on COVID mask shop for cookie consent failure Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Art. 5, 12, 13 Cookies IP Address Personal Data Jan 16, 2026
GBP 120,000 ICO (UK) - Allay Claims Ltd Allay Claims Ltd (the controller) sent over 4 million direct marketing text messages to individuals promoting a different entity’s services. The DPA received over 48,000… United Kingdom Direct Marketing Consent Telecommunications Jan 15, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Processors Controllers NL Jan 13, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PREMIER RESTAURANTS ROMANIA SRL. The controller failed to implement adequate technical and organisational measures, resulting… ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Law Enforcement Jan 13, 2026
€200 DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis A medical student (the controller) worked as a ward attendant at a hospital. Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the… Austria ·Art. 4, 5, 6 +1 Legitimate Interest Healthcare Personal Data Jan 12, 2026